oss-sec mailing list archives
CVE-2018-1066 : kernel - CIFS - Null pointer dereference in ntlmv2 response client crash.
From: Wade Mealing <wmealing () redhat com>
Date: Tue, 6 Mar 2018 14:07:43 +1000
Gday, Dan Aloni reported to Red Hat that there was a flaw in the CIFS client implementation in kernel that could cause a null pointer dereference and panic the a Linux CIFS client. It would require the server to implement the CIFS protocol incorrectly or momentarily impersonate the CIFS server during session recovery (such as when the server was shut down, or the network conditions were bad). The attacker would need to return an empty "TargetInfo" in the NTLMSSP setup negotiation response causing the null pointer dereference when interpreted by the client. Report ( and patch ) https://patchwork.kernel.org/patch/10187633/ RedHat Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=1539599 Thanks, Wade Mealing Red Hat Product Security
Current thread:
- CVE-2018-1066 : kernel - CIFS - Null pointer dereference in ntlmv2 response client crash. Wade Mealing (Mar 05)